PT-2026-8021 · Google · Google Chrome
Shaheen Fazim
·
Published
2026-01-01
·
Updated
2026-04-01
·
CVE-2026-2441
CVSS v2.0
10
High
| AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 145.0.7632.75/76 and 144.0.7559.75 (Linux)
Description
Google Chrome has a high-severity use-after-free vulnerability (CVE-2026-2441) in the CSS engine that is actively exploited in the wild. This flaw allows attackers to execute arbitrary code inside the browser sandbox via a crafted HTML page. The vulnerability is related to CSS font feature values processing and can be triggered by visiting a malicious webpage. A public proof-of-concept (PoC) exploit is available. The vulnerability affects all Chromium-based browsers.
Recommendations
Update Google Chrome to version 145.0.7632.75 or later on Windows and macOS, or to version 144.0.7559.75 or later on Linux. Restart the browser after applying the update.
Exploit
Fix
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome